Impact
The JMedia extension for Joomla contains an SSRF flaw that allows a remote URL to be downloaded by the extension. Remote URL downloads could target internal or reserved addresses, potentially exposing internal network data or services. This may enable an attacker to read or manipulate internal resources that should not be exposed to the public internet.
Affected Systems
Any installation of the JMedia extension from themexpert.com for Joomla with a version earlier than 1.6.0. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 5.1 describes a moderate risk. The EPSS score is < 1%, and the vulnerability is not in the CISA KEV catalog, indicating no broad exploit campaigns have been documented. Exploitation would require the ability to trigger the remote URL download feature, which could be possible from a public-facing request or via an authenticated session, depending on how the extension is configured. Successful exploitation would give the attacker direct resolution of internal IP addresses or services, allowing data exfiltration or further lateral movement. The likely attack vector is inferred from the extension’s public-facing download capability.
OpenCVE Enrichment